Compliance

Cyber Essentials,explained

6 min read · Updated June 2026

Cyber Essentials is the UK government-backed scheme, run under the NCSC, built on five technical controls that protect against the most common internet-based attacks. Base Cyber Essentials is a verified self-assessment; Cyber Essentials Plus adds an independent, hands-on technical audit of the same five controls.

What Cyber Essentials is

Cyber Essentials is a UK certification scheme, backed by the government and run under the National Cyber Security Centre (NCSC). It is deliberately a baseline: five technical controls that block the bulk of commodity, internet-based attacks, rather than a full management system.

That simplicity is the point. It is a quick, recognised first step, and it is frequently a requirement for UK public-sector contracts.

The five controls

  • Firewalls: control the traffic in and out of your networks and devices.
  • Secure configuration: remove or disable unnecessary functionality and default accounts.
  • Security update management: keep software supported and patched promptly.
  • User access control: manage accounts, apply least privilege, and protect admin access.
  • Malware protection: defend devices with anti-malware, allow-listing, or sandboxing.

Cyber Essentials vs Cyber Essentials Plus

Both cover the same five controls. The difference is how they are assured. Cyber Essentials is a self-assessment questionnaire that is independently verified. Cyber Essentials Plus adds a hands-on technical audit, where an assessor tests that the controls are actually in place. Plus carries more assurance weight with buyers.

How it relates to ISO 27001

Cyber Essentials is a baseline of five technical controls; ISO 27001 is a full information-security management system. The five themes are a subset of what ISO 27001 covers, so Cyber Essentials is a sensible quick win, and the work carries over if you go on to pursue ISO 27001 later.

How to get certified

  1. 1Confirm the scope: the devices, users, and networks in your assessment.
  2. 2Implement the five controls and gather evidence that they are in place.
  3. 3Complete the verified self-assessment for Cyber Essentials.
  4. 4Book the hands-on assessment if you need Cyber Essentials Plus.
  5. 5Recertify annually, keeping the evidence current in between.

Frequently asked questions

What is the difference between Cyber Essentials and Cyber Essentials Plus?

Both cover the same five technical controls. Cyber Essentials is a verified self-assessment, while Cyber Essentials Plus adds an independent, hands-on technical audit that checks the controls are actually in place. Plus carries more assurance weight.

Who needs Cyber Essentials?

Any UK organisation wanting a recognised security baseline, and in particular suppliers bidding for UK public-sector contracts, which often require Cyber Essentials or Cyber Essentials Plus.

How long does Cyber Essentials last?

Certification runs for a year, so organisations recertify annually. Keeping the five controls and their evidence current in between makes each recertification straightforward.

Do this in a fraction of the time

Diligio centralises your approved answers, drafts each response grounded in your sources, and independently verifies it before you review. RFPs, DDQs, and security questionnaires, answered from one knowledge base.

Related guides